Summary
This brief chapter covered the very important topic of building an API security strategy and saw the theory we have learned about API security applied to real-world API development. Understanding who owns your APIs is important in understanding how to drive the messaging around the need for API security. A broad-based approach involving the CISO or IT security organization and their colleagues in the API product development teams is likely to produce the best results since this will include API security touchpoints across all phases of the SDLC.
First, we learned how to plan an API security initiative by understanding our objectives (the “why”) and then understanding our current state to form our strategy. We then looked at running a program, focusing on the critical step of building our team and selecting our KPIs to gauge our progress.
Finally, your own continued learning is important for staying on top of emerging threats and changes in technology landscapes...